Maximilian Zinkus

dblp:236/5576 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
4since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 4 since 2021Computer networks · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2024 SocIoTy: Practical Cryptography in Smart Home Contexts
abstract
Smartphones form an important source of trust in modern computing. But, while their mobility is convenient, smartphones can be stolen or seized, allowing an adversary to impersonate the user in their digital life: accessing the user's services and decrypting their sensitive files. With this in mind, we build SocIoTy, which leverages a user's existing IoT devices to add a context-sensitive layer of security for non-expert users. Instead of assuming the existence of dedicated hardware, SocIoTy re-uses the devices of a user's smart home to provide cryptographic services, which we term at-home cryptography. We show that at-home cryptography can be built from simple cryptographic primitives, and that our SocIoTy solution is able to provide useful functionalities, like two-factor authentication (2FA) and secure file storage, while protecting against powerful adversaries in this setting. We implement and evaluate SocIoTy in real-world use cases and provide microbenchmarks for individual cryptographic operations on realistic models of IoT devices. We also provide full benchmarks of an end-to-end deployment on a simulated smart home, using a smartphone and 9 IoT devices to generate and display 2FA one-time passwords in less than 200 milliseconds. SocIoTy is able to provide strong, practical cryptography while binding its execution to the smart home itself, all without requiring additional hardware.
Tushar M. Jois, Gabrielle Beck, Sofia Belikovetsky, Joseph Carrigan, Alishah Chator, Logan Kostick, Maximilian Zinkus, Gabriel Kaptchuk, Aviel D. Rubin
Proc. Priv. Enhancing Technol.7
2023 McFIL: Model Counting Functionality-Inherent Leakage
Maximilian Zinkus, Yinzhi Cao, Matthew Green 0001
USENIX Security Symposium1
2022 One-Time Programs from Commodity Hardware
Harry Eldridge, Aarushi Goel, Matthew Green 0001, Abhishek Jain 0002, Maximilian Zinkus
TCC (3)5
2022 SoK: Cryptographic Confidentiality of Data on Mobile Devices
abstract
Mobile devices have become an indispensable component of modern life. Their high storage capacity gives these devices the capability to store vast amounts of sensitive personal data, which makes them a high-value target: these devices are routinely stolen by criminals for data theft, and are increasingly viewed by law enforcement agencies as a valuable source of forensic data. Over the past several years, providers have deployed a number of advanced cryptographic features intended to protect data on mobile devices, even in the strong setting where an attacker has physical access to a device. Many of these techniques draw from the research literature, but have been adapted to this entirely new problem setting.
Maximilian Zinkus, Tushar M. Jois, Matthew Green 0001
Proc. Priv. Enhancing Technol.1
2020 Automating the Development of Chosen Ciphertext Attacks
Gabrielle Beck, Maximilian Zinkus, Matthew Green 0001
USENIX Security Symposium2
2019 PIDIoT: Probabilistic Intrusion Detection for the Internet-of-Things
abstract
The Internet-of-things promises sweeping change through increased connectivity and ubiquitous integration of technology into our lives. However, as we create economies of scale for data aggregation and processing, we also create attractive targets for various adversaries. In this work we design a lightweight, probabilistic intrusion detection system, or PIDIoT. We design PIDIoT to use operational measurements from IoT devices, with lightweight hash functions and Bloom filters to perform fuzzy anomaly detection. We experiment with IoT devices operating in an isolated environment, and we show that we can detect over 90% of simulated attacks. While we do not propose PIDIoT as a comprehensive solution for IoT defense, we make a case for its use as part of a layered defense strategy.
Maximilian Zinkus, Foaad Khosmood, Bruce DeBruhl
GLOBECOM1
2019 Fakesbook: A social networking platform for teaching security and privacy concepts to secondary school students
abstract
As frequent users of social networking applications, middle and high school students are well-suited for curricular interventions that leverage these technologies. Allowing students to see "behind the curtain" of these applications provides them with a unique opportunity to better understand the discipline of computer science upon which these technologies are built and influences their perceptions of computer security and privacy. We present a novel social networking simulation that allows students to create a social network account, including profile data and images, and to manage privacy settings and friend connections. The platform, named Fakesbook, presents students with a visualization of the social network as a graph, enabling them to observe the spread of profile data (theirs and others') depending on friend connections and choices of privacy settings. We additionally present our lab curriculum which uses Fakesbook to enable active learning and adversarial thinking to engage students and build agency with regard to privacy and computing concepts. We deployed and, over several years, evaluated our platform and curriculum with hundreds of students from a diverse set of backgrounds at educational events designed to introduce these populations to computer science, cybersecurity, and privacy. Survey results indicate that students gained or deepened their understanding of online privacy and security and that 86% of participants found that Fakesbook helped them "think about privacy and computer security."
Maximilian Zinkus, Oliver Curry, Marina Moore, Zachary N. J. Peterson, Zoë J. Wood
SIGCSE1